You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何提前设置IP生成URL,从IPinfo提取IP信息?

问题解决与优化方案

错误原因分析

你之前的代码问题出在两个地方:

  1. _IP变量里多余的单引号,导致拼接后的URL包含无效的引号字符(比如https://ipinfo.io/'1.1.1.1'/json),无法被IPinfo识别。
  2. strcat里错误地加入了@"语法标记——@是Kusto的逐字字符串前缀,属于语法范畴,不能作为字符串内容拼接。

修正后的基础写法

直接构造正确的URL字符串即可,不需要额外的引号或语法标记:

let _IP = "1.1.1.1"; // 直接填写目标IP,无需单引号
let _link = strcat("https://ipinfo.io/", _IP, "/json");
let IPCheck = externaldata(ip: string, city: string, region: string, country: string, org: string)
[_link] with(format=multijson);
IPCheck

更优的复用方案(适配SigninLogs等场景)

将IP查询逻辑封装成可复用函数,方便在批量场景(比如SigninLogs)中直接调用:

1. 定义查询函数

.get_ip_info(ip:string) {
    let target_url = strcat("https://ipinfo.io/", ip, "/json");
    externaldata(ip: string, city: string, region: string, country: string, org: string)
    [target_url] with(format=multijson)
}

2. 单个IP查询

.get_ip_info("8.8.8.8")

3. 在SigninLogs中批量关联IP信息

SigninLogs
| where isnotempty(IPAddress) // 过滤空IP记录
| invoke get_ip_info(IPAddress) // 批量调用函数查询IP信息
| project TimeGenerated, UserPrincipalName, IPAddress, city, region, country, org // 按需选择字段展示

这种方式既简化了单IP查询的修改流程(只需要改函数参数),也能无缝适配日志分析等批量IP查询场景,提升代码复用性。

内容的提问来源于stack exchange,提问作者Shmalc

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 18:40:43